BAGHOLDER
  • Home
  • Terms
  • How BAGHOLDER Works
  • Support

Privacy Policy

Version 1.7 — Last updated: September 13, 2026

This Privacy Policy describes how BAGHOLDER ("we," "us," or "our") collects, uses, and protects your information when you use our mobile application.


Information Stored on Your Device

BAGHOLDER stores the following data locally on your device using encrypted storage (iOS Keychain / Android Keystore for secrets, an encrypted local database for structured data):

  • Your bags and token lists
  • Purchase history and pending orders
  • Send records, including the addresses you send to (stored with your send records and carried in your encrypted backup)
  • Blocked-attempt audit log (kept for 365 days for support purposes; a structured mirror is also stored on our server — see below)
  • Portfolio snapshots
  • Diagnostic logs
  • State of residence
  • Date of birth verification status
  • Wallet address
  • App settings and preferences
  • Disclosure and terms acceptance records
  • Account protection data: a random identifier the app generates for this installation (it is not a device identifier), and a setting recording that this phone confirms sends, sales and cash-outs with your BAGHOLDER PIN rather than Device Authentication. Both are kept in your phone’s secure storage. Both are sent to our server, over an encrypted connection, with each account-protection check; the server keeps only a one-way hash of the identifier, and that setting (see below). Your PIN itself is not stored on your device.

Other than the blocked-attempt mirror and the account protection data noted above, this data is NOT transmitted to our servers and remains exclusively on your device.

Encrypted Cloud Backup

To protect against data loss (device replacement, app reinstallation, or accidental storage clearing), BAGHOLDER automatically creates an encrypted backup of your on-device data. This backup is encrypted on your device using a key derived from your wallet before transmission. We store the encrypted data on our server but cannot decrypt, read, or access its contents. Only your wallet can unlock the backup.

The backup includes: your bags, your buys, your sells and cash-outs, your token swaps, your sends (including the addresses you sent to), stablecoin conversions, BAGHOLDER’s platform fees, gas purchases, your app settings and your portfolio snapshots — everything the app records on your device except caches and in-flight queues, which are rebuilt rather than carried. An upload follows shortly after your records change, rather than on a schedule. It can be delayed — if you are offline, or if this device has not yet finished restoring an existing backup — in which case the app retries and tells you if it cannot. On reinstall or device change, signing in recovers your wallet, which automatically decrypts and restores your data.

You can delete your backup at any time by deleting your account in Settings.


Information Stored on Our Server

Our server stores the following data in a secured database:

  • Payment profile (wallet address, transaction volume)
  • Payment charge records (payment provider session ID, charge amount, fee amount, wallet address, chain, status, timestamp)
  • Gas funding records (wallet address, transaction hash, native-token gas amount, chain, timestamp)
  • Fee sweep records (chain, amount, transaction hash, fee type, timestamp) retained indefinitely as the financial and audit record
  • Per-token swap outcomes (chain, symbol, amount, DEX used, success/failure reason, transaction hash)
  • Cached wallet token balances: our server reads the token balances of your addresses on your behalf, covering all the coins you hold and not only the tokens in your bags, so the app can show them, and keeps a short-lived cache (so we do not pay third-party RPC providers for repeat reads of the same on-chain data)
  • Send check records: when you send, the recipient address and the token are sent to our server once, to be checked against U.S. sanctions lists. The recipient address is not stored. We keep a record of the attempt: your wallet address, the network, the token, the state code, and whether the send was allowed, plus its dollar value when known.
  • Account protection records, kept for the PIN and phone checks described in the Terms of Service (“Your PIN and Account Protection”). Per account, keyed by your wallet address: a salted, one-way scrambled form of your BAGHOLDER PIN (never the PIN itself), a count of wrong PIN entries made from phones on which your PIN has never been entered and any lock that results, the times your PIN was set or reset, which phone asked for a reset, and when a reset was last cancelled. For the 24 hours after a reset we also keep the scrambled form of the previous PIN, so that the reset can be cancelled. Per phone your account is signed in on: a one-way hash of a random identifier the app generates (not a device identifier), computed together with your account, so the same phone signed in to two accounts has a different stored value on each; whether it is an Android phone or an iPhone; when it was first and last seen; whether it is trusted or frozen; whether the app found that phone with no screen lock; and a count of wrong PIN entries made on that phone and any lock that results. When an account has more than six of these phone records, those for phones on which your PIN was never entered, which are not frozen and have not been seen for 30 days, are deleted. Your PIN is sent to our server over an encrypted connection to be checked; we do not store it in a form that can be read back, and we cannot recover it for you.
  • Solana ATA membership cache (which token accounts your Solana wallet has, so we charge the correct account-creation rent)
  • Sell (cash-out) session records: the payout provider and sub-provider identifier used, your wallet address, the chain, the asset, the crypto amount, your chosen payout method, the state code used for the eligibility check, an idempotency key, the provider's transaction identifier, the redirect link to the provider's page, the status, and any error text returned to us. As the sell progresses we also record what the provider reports back: its own status, the fiat payout amount and currency, the provider's fee, the settled crypto amount, the deposit transaction hash, and timestamps. These records contain no personal information beyond your wallet address and state code — the same categories as a payment charge record.
  • Sell fee records, created only when a BAGHOLDER sell fee applies to a sell: your wallet address, the chain, the asset, the gross and fee amounts in that asset, the fee rate, the price reference used, the fee transaction hash and nonce, the amount verified on-chain, the status (armed, verified, or skipped and why), the sell disclosure version and fee label you accepted, the payout session reference, and any refund transaction hash. These records contain no personal information beyond your wallet address.
  • Payout provider webhook records: the raw notification body a payout provider sends us about your order, stored so that we process each notification exactly once and ignore duplicates. This body can contain your wallet address and the amounts involved. It does not contain identity documents.
  • Per-state activity aggregates and snapshots: rolling-12-month totals of purchase volume, completed cash-out (sell) volume, platform fees, purchase count, and active-user count, broken out by the state code recorded on each transaction. Used to monitor compliance with state-level thresholds such as California Financial Code §3103(b)(9). A completed sell counts toward these totals on the same basis as a purchase. A snapshot of these aggregates is persisted to a separate table approximately once per calendar quarter, to provide a historical record of what we knew when. The aggregates and snapshots do not contain wallet addresses or individual purchase or sell records — only state-level totals.
  • Verified wallet binding pair if you bind a Solana wallet (EVM address ↔ Solana address, signed proof)
  • Wallet-to-account binding (a record linking each wallet address you sign in with to the account identifier issued by our wallet provider, Privy). Used to enforce the gas- funding Sybil cap and suspension provisions described in the Terms of Service — not a per-account limit on how much you may purchase. No additional personal information is collected through this binding.
  • Suspended-wallet list (wallet addresses we have refused service to, with a short text reason and timestamp). Used to enforce the suspension provisions in the Terms of Service. Suspension blocks only starting a new payment for a purchase through the App, receiving network gas from BAGHOLDER, and creating new shared bags; suspended accounts retain the ability to export their private keys through the wallet provider's hosted page.
  • Anonymized usage events (e.g., app opens, feature usage, purchase outcomes) associated with your wallet address only and automatically deleted after 1 year
  • Blocked-attempt audit log mirror (chain, amount requested, token symbols, block reason, timestamp) — required to demonstrate compliance with state eligibility, age, and limit rules. Retained for the regulatory window (no automatic deletion).
  • Token registry liquidity events (token de-list/re-list history with reason — used to power the "this token was removed" message in the app)
  • Shared bag configurations (token lists only, no personal data) if you choose to share a bag via the sharing feature. Unused shared bags are automatically deleted after 1 year
  • The encrypted cloud backup of your local app data if you opt in — encryption key is derived from your wallet signature and the server cannot decrypt it
  • Onboarding attestation records (see below) — the pass/fail outcome recorded at each signup gate (age, state, and legal-document review), keyed to a device identifier rather than your wallet, and retained for about 1 year. On a failed age check we record only an age band, never your date of birth.

Onboarding attestation records

During signup, before you have a wallet, the App records the pass/fail outcome at each eligibility gate (age verification, state selection, and legal-document review) so we can maintain a compliance audit trail and apply anti-abuse and rate-limiting safeguards against automated or repeated evasion. These records are keyed to a device identifier rather than your wallet, name, or email, and are retained for about one year. On a failed age check we record only an age band — never your date of birth. We also record the request IP at the moment of state attestation as a secondary cross-reference for the audit trail; your self-attested state of residence is the primary record. These records are never linked to your wallet, payment, or order records, and do not include your name, email, or any other personally identifiable information (PII).

Important: your email address may pass through our server when you make a buy — it is forwarded to our payment provider as required by their payment API. The transit is encrypted (HTTPS) and the value is discarded immediately after it's sent. No row of any database on our server contains your email at rest.


Information We Do NOT Collect

BAGHOLDER does not store on any server:

  • Private keys or wallet seed phrases
  • Your name
  • Your email address (passes through in-transit on each buy only — see above)
  • Date of birth (only the age band on a rejected attempt — see "Onboarding attestation records" above)
  • Biometric data (device authentication returns a boolean only)
  • Bank account credentials or login information
  • Social Security numbers or government IDs
  • Location data (your IP address briefly touches our server during each buy and is forwarded to our payment provider for fraud-risk scoring — we do not log or store it; the single exception is the attestation-event audit trail described above, which is never linked to your wallet, payment, or order records)

Third-Party Services

BAGHOLDER integrates with third-party services that process your data under their own privacy policies:

Payment provider

Our licensed payment provider processes your fiat payment and delivers a USD stablecoin (currently USDC) directly to your wallet, and performs any identity checks under its own privacy policy. You can pay as a guest with Apple Pay, Google Pay, card, and more depending on your provider — no account needed to get started. On every buy we pass your wallet address, the amount, and the destination chain to the provider; the provider collects any payment or identity details directly from you on its own payment screen. We receive only confirmation of successful delivery of the stablecoin.

Tax reporting: BAGHOLDER is a non-custodial software tool and does not prepare or file tax forms on your behalf. Buying cryptocurrency through our integrated onramp is generally not itself a taxable event under current US tax law. But every time tokens are swapped for other tokens — which happens automatically as part of every BAGHOLDER buy (the stablecoin your payment bought is swapped into the tokens you selected) — and every later sale, cash-out, or other disposal, can be a taxable event for which you are responsible. BAGHOLDER does not report your transactions to any tax authority and does not issue tax forms. Any tax form relating to your crypto activity would come from a third party — such as the payout provider you cash out through, or another platform where you sell — not from BAGHOLDER. Tax rules vary by jurisdiction and change over time — always consult a qualified tax advisor for your specific situation.

Off-ramp payout provider (selling)

Where selling is available, your cash-out is handled by a third-party payout provider — today Transak, reached through the Coindisco aggregator. The provider verifies your identity on its own hosted page, under its own privacy policy. It collects your identity documents and payout details directly from you — typically a government photo ID, your Social Security number, a selfie, and your card details. BAGHOLDER never receives, sees, forwards, or stores any of it, and no BAGHOLDER database has a column for it.

We do not send the provider your name or email address on a sell. We send only what is needed to price and create the order: the chain, the asset, the amount, the payout method, the state code, and your wallet address. Your IP address is forwarded in the request header so the provider can run its own geography and fraud checks — it passes through only; we do not log or store it, and no sell record has an IP column.

We receive back only the order status, the fiat payout amount and currency, the provider's fee, the settled crypto amount, and the deposit transaction hash. BAGHOLDER is not the buyer or the seller, never receives the crypto you sell or the cash you are paid, and cannot reverse a transfer. See Terms of Service §7.1.

Privy (wallet creation)

Privy creates and manages your non-custodial embedded wallet using advanced cryptographic techniques. Privy may collect your email address or social login credentials for authentication. We do not receive or store these credentials.
See: privy.io/privacy

Firebase Crashlytics (crash reporting)

We use Google's Firebase Crashlytics for crash reporting. When the app crashes, Crashlytics sends Google a crash report that includes a Crashlytics Installation UUID (an anonymous identifier Google generates per app install — not linked to any account or wallet on our side), your IP address (used by Google for geographic crash distribution and discarded afterward), the stack trace and exception details, device model, and OS version. We strip wallet addresses and Solana addresses from error messages before sending. Crash reports do NOT contain your name, email, phone, or wallet address.
See: firebase.google.com/support/privacy

Blockchain infrastructure providers (RPC)

Third-party providers relay blockchain data between your wallet and the network. They may see your wallet address in transaction requests. No personal data is shared beyond the wallet address.

Jupiter (Solana DEX aggregator)

For purchases on Solana, our server sends your swap parameters (input token, output token, amount, your wallet address) to Jupiter's public aggregator API so it can return a routed swap transaction your wallet then signs. Jupiter sees only the wallet address and swap parameters.
See: jup.ag/legal/terms-of-use

CoinGecko (market data)

We fetch public cryptocurrency market data from CoinGecko. No user data is shared with CoinGecko.

DefiLlama (near-live prices)

We fetch public near-live token prices from DefiLlama, keyed only by the token identifier. No user data is shared with DefiLlama.


Data Retention

  • Local data: stored until you delete your account or uninstall the app.
  • Server payment records, gas funding records, fee sweep records, swap fee and swap check records, and send check records: retained indefinitely as the financial and audit record, for tax and accounting purposes.
  • Swap event logs: up to 1 year, then deleted. Error reports: up to 90 days, then deleted. Both are deleted on account deletion.
  • Payment profiles: retained while your wallet is active.
  • Account protection records (the scrambled form of your PIN, and the records of the phones your account is signed in on): retained while your account is active, deleted on account deletion; some phone records are deleted earlier, as described above.
  • Anonymized usage events: retained for 1 year, then automatically deleted.
  • Shared bag configurations: automatically deleted after 1 year of inactivity.
  • Blocked-attempt audit log: retained on your device for 365 days, then automatically pruned.
  • Sell (cash-out) records where the order was created: retained indefinitely as the financial and audit record, on the same basis as payment charge records. The wallet address is retained raw and replaced with a one-way hash on account deletion.
  • Sell fee records: retained indefinitely as the financial and audit record, on the same basis as sell records. The wallet address is retained raw and replaced with a one-way hash on account deletion, when the fee and refund transaction hashes are also cleared.
  • Sell records where creation failed before the order reached the provider: deleted after 90 days. A sell whose outcome we could not confirm is kept, because deleting a record of a transfer that may have happened would destroy the audit trail.
  • Payout provider webhook records: the raw body is blanked 30 days after the notification is processed, and the record itself is deleted after 180 days.

Your Rights

You have the right to:

  • Export your account’s keys at any time from Settings, to use them in a wallet app of your choice.
  • Delete your account using the Delete Account feature in Settings. Our server is cleaned up first: your encrypted backup and its history, shared bags, wallet bindings, caches, swap event logs, error reports and your account protection records (the scrambled form of your PIN and the records of the phones your account is signed in on) are deleted. If our server cannot be reached or any step fails, nothing is deleted and the app asks you to try again. Then all data on your phone is erased and your wallet session is disconnected. Your wallet and coins are not deleted: they remain yours on the blockchain. Your Privy login is not deleted; signing in again with the same login reopens the same wallet (contact Privy to delete the login itself). Financial records we are required to keep — payment charges, treasury ledger, gas fundings, usage events, sell (cash-out) records, sell fee records, swap fee and swap check records, and send check records — are kept, with your wallet address removed and replaced by a keyed one-way hash. Their amounts, dates, chain and state code remain, so this removes your address but is not full anonymization. For sell records we additionally clear the provider link, the provider's transaction identifier, any error text, and the deposit transaction hash, and we blank the stored provider webhook bodies that referenced you. For sell fee records we clear the fee transaction hash and any refund transaction hash.
  • View your transaction history at any time within the app.
  • Request deletion of server-stored data by contacting us at support@getbagholder.com.

California Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to know what personal information we collect and how it is used.
  • Right to delete your personal information.
  • Right to opt out of the sale of your personal information. We do NOT sell your personal information.
  • Right to non-discrimination for exercising your rights.
  • Right to correct inaccurate personal information.
  • Right to limit use of sensitive personal information. We do not collect sensitive personal information.

To exercise these rights, contact us at support@getbagholder.com.


Geographic Availability

BAGHOLDER is available in 41 U.S. states. BAGHOLDER is not available in New York, Connecticut, Louisiana, Vermont, New Mexico, the District of Columbia, Pennsylvania, Oregon, Arkansas, or West Virginia.


Children's Privacy

BAGHOLDER is not intended for anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information.


Security

We use industry-standard security measures to protect your data, including:

  • Encrypted local storage (iOS Keychain / Android Keystore)
  • HTTPS for all server communication
  • Advanced cryptographic key management via our wallet provider
  • API keys stored server-side only, never on your device

No system is 100% secure. You are responsible for securing access to your device.


Changes to This Policy

We may update this privacy policy from time to time. The current version is always available in the app under Settings. If we make material changes, you will be asked to review and accept the updated policy.


Contact Us

If you have questions about this privacy policy, contact us at:
support@getbagholder.com
getbagholder.com

Home Privacy Policy Terms of Service How BAGHOLDER Works Support

© 2026 BAGHOLDER. All rights reserved.